mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-02 04:43:58 +00:00
vault + teams: filter secrets by category, export to CSV, simpler help
Every secret now has a category derived from its name (db, social, server,
api, cloud, finance, crypto, ai, email, messaging, storage, dns, analytics,
devtools, auth, config, other). One rule table in @logicsrc/opencreds serves
both vaults; services win over generic words, so STRIPE_WEBHOOK_SECRET is
finance, not auth. Checked against the 1,208 distinct key names in the
profullstack team: 74 fall to "other".
Team vaults (where the shared .env secrets live):
- teams categories [team] the filter words, with per-category counts
- teams secrets <team> [project] [env] --category/-c --search/-s
names + categories, never decrypts; --format csv
- teams export <team> [project] [env] --category -o file.csv [--yes]
decrypts into team,project,env,category,key,
value,updated_at (0600); skips vaults without a
grant and names them
Personal vault (OpenCreds):
- vault list --category, and the category column in list output
- vault export --format csv: one flat row per item, keeps key/account
secrets that a Bitwarden CSV drops; --category on every export format
DX:
- examples in `logicsrc vault help` / -h / --help that start by saying which
of the two vaults you want, plus examples on teams and each subcommand
- password prompts go to stderr, so eval "$(logicsrc vault unlock)" works
- hints name the command you actually ran (logicsrc vault init, not
opencreds init)
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
156c9164a9
commit
a0f8f2c125
11 changed files with 846 additions and 19 deletions
|
|
@ -292,6 +292,37 @@ automation, write the link explicitly with
|
|||
directory path and team/project/environment names; they live in the user's
|
||||
LogicSRC config directory, never in the project and never contain secret values.
|
||||
|
||||
### Finding and exporting secrets by category
|
||||
|
||||
Every secret has a category, worked out from its name: `DATABASE_URL` is `db`,
|
||||
`TWITTER_API_KEY` is `social`, `SSH_PORT` is `server`, `TMDB_API_KEY` is `api`.
|
||||
A named service wins over a generic word, so `STRIPE_WEBHOOK_SECRET` is
|
||||
`finance` (it belongs with the rest of Stripe) rather than `auth`.
|
||||
|
||||
```bash
|
||||
logicsrc teams categories # the categories and what each catches
|
||||
logicsrc teams categories acme # how many secrets acme has in each
|
||||
|
||||
logicsrc teams secrets acme # every secret NAME in every vault
|
||||
logicsrc teams secrets acme --category db # only databases (aliases work: database, sql)
|
||||
logicsrc teams secrets acme -c social,api # several at once
|
||||
logicsrc teams secrets acme web prod -s stripe # one vault, names containing "stripe"
|
||||
logicsrc teams secrets acme --format csv # names as CSV, still no values
|
||||
|
||||
logicsrc teams export acme --category db -o db.csv # decrypt into a CSV
|
||||
logicsrc teams export acme web prod -o web-prod.csv --yes # one vault, no prompt
|
||||
```
|
||||
|
||||
`secrets` never decrypts anything. `export` decrypts on your machine and writes
|
||||
`team,project,env,category,key,value,updated_at`, one row per secret, mode 0600.
|
||||
It asks before writing plaintext; pass `--yes` in scripts. Vaults you have no
|
||||
grant for are skipped and listed rather than failing the export.
|
||||
|
||||
The categories are `crypto`, `ai`, `finance`, `email`, `messaging`, `social`,
|
||||
`storage`, `db`, `dns`, `analytics`, `devtools`, `cloud`, `server`, `auth`,
|
||||
`api`, `config` (settings that are not secrets) and `other`. The same table
|
||||
filters the personal vault: `logicsrc vault list --category db`.
|
||||
|
||||
### Rotating a vault key
|
||||
|
||||
```bash
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue